8.1.16 Set 'Automatic prompting for file downloads' to 'Enabled:Disable'

Information



This policy setting determines whether users will be prompted for non user-initiated file
downloads. Regardless of this setting, users will receive file download dialogs for user-
initiated downloads. The recommended state for this setting is- Enabled-Disable.

*Rationale*

Users may accept downloads that they did not request, those downloaded files may include
malicious code.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to
Enabled.

Computer Configuration\Administrative Templates\Windows Components\Internet
Explorer\Internet Control Panel\Security Page\Internet Zone\Automatic prompting for
file downloadsThen set the Automatic prompting for file downloads option to Disable.

Impact-If you enable this setting, users will receive a file download dialog for automatic download
attempts. If you disable or do not configure this setting, file downloads that are not user-
initiated will be blocked, and users will see the Information Bar instead of the file
download dialog. Users can then click the Information Bar to allow the file download
prompt.

Default Value-
Disabled

See Also

https://workbench.cisecurity.org/files/1518

Item Details

Audit Name: CIS IE 11 v1.0.0

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7a., CSCv6|3.1

Plugin: Windows

Control ID: 763627e3404ae2c340d246e0731e5a3ecb43b53c3847fda81871091f1eab0060